An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version 7.1.4 and below, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to obtain sensitive data via crafted HTTP or HTTPs requests.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-23-434 | Broken Link |
Configurations
Configuration 1 (hide)
|
History
16 Oct 2025, 14:47
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:fortinet:fortiadc:7.4.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:* |
|
| CWE | NVD-CWE-noinfo | |
| First Time |
Fortinet
Fortinet fortiadc |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-23-434 - Broken Link |
14 Oct 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-14 16:15
Updated : 2025-10-16 14:47
NVD link : CVE-2025-59921
Mitre link : CVE-2025-59921
CVE.ORG link : CVE-2025-59921
JSON object : View
Products Affected
fortinet
- fortiadc
CWE
